- Ceiba software
- |
- General information security policy
INTRODUCTION
Ceiba Software’s information security policy establishes the strategic and organizational foundations for the purpose of preserving and protecting information against unauthorized modifications, destructions or disclosures, whether accidental or intentional, throughout its life cycle.
Ceiba Software defines an appropriate level of security to protect its technological infrastructure and data, developing prevention and maintenance mechanisms in accordance with current international information security management standards. This document presents the organization’s security posture, prioritizing at all times the trust of our clients, employees, suppliers, and stakeholders.
AIM
To establish the guidelines, plans, and mechanisms that guarantee the security of Ceiba Software’s information, covering all business operations and procedures. This is done to preserve the confidentiality, integrity, and availability of information assets, complying with current regulatory, contractual, and legal obligations, and maintaining a strong position against the risks and threats of the digital environment.
- Confidentiality: Keep information accessible only to duly authorized personnel, clients, or services.
- Integrity: Preserving the consistency, accuracy, and reliability of data throughout its lifecycle.
- Availability: Ensure that information and services are accessible when required by authorized entities.
REACH
This policy is mandatory and applies to:
- The organization’s information in any of its forms (physical or digital), regardless of its storage medium, transport network or system used to process or transfer it.
- All employees (directly or indirectly), partners, contractors, vendors, suppliers and any third party who accesses Ceiba Software’s networks and information resources.
- Information resources that have been entrusted to Ceiba Software by external entities or corporate clients.
RESPONSIBILITIES
Information security at Ceiba Software is a shared commitment. Specific roles have been defined within the organization to ensure proper risk management:
- Senior Management and IT Management: Responsible for directing the technology and cybersecurity strategy, ensuring alignment with business objectives and providing the necessary resources to maintain effective controls.
- Cybersecurity Leaders: Responsible for developing the security program, maintaining policies, evaluating regulatory compliance, and coordinating incident response.
- Employees, Contractors and Third Parties: Every user of Ceiba Software systems has the fundamental duty to understand the basic controls, protect information against unauthorized disclosure, respect acceptable use policies and report any anomalies or security incidents.
GENERAL GUIDELINES OF THE MANAGEMENT SYSTEM
Ceiba Software has a comprehensive framework of specific controls and policies that support the proper protection of assets, covering the following fundamental domains:
- Classification and Access Control: All information is classified according to its criticality. Access to systems and applications is governed by the principle of least privilege, employing unique identifiers, multi-factor authentication (MFA), and a rigorous user lifecycle management system.
- Physical and Environmental Security: Access to critical facilities is strictly restricted and monitored. Controls are in place for the protection of workstations and the secure disposal of physical and digital media.
- Cryptography and Secure Transfer: Data encryption is required both at rest (e.g., workstations, storage) and in transit (secure channels such as HTTPS, TLS, VPN). Transferring sensitive information externally requires formal agreements (NDAs) and approved corporate tools.
- Antimalware Protection and Vulnerability Management: The organization maintains continuous processes of patch installation, hardening of configurations and state-of-the-art antimalware systems in all its environments.
- Cloud Security and Backups: The infrastructure deployed in cloud services operates under strict service level agreements (SLAs), perimeter controls, encryption, and proven backup policies to ensure business resilience.
- Relationship with Third Parties and Suppliers: Mandatory minimum security requirements are established from the contractual stages, ensuring that every supplier who accesses corporate data complies with Ceiba’s cybersecurity standards.
- Compliance and Protection of Personal Data: Ceiba ensures regulatory compliance in the handling of personal data, limiting the collection, storage and processing only to legitimate and authorized purposes, supported by continuous monitoring, recording and auditing (logging) mechanisms.
CULTURE OF SAFETY AND COMPLIANCE
The organization promotes a culture of constant awareness, providing continuous training to all employees to strengthen the ability to respond to cyber threats (e.g., phishing, social engineering).
Compliance with this policy and its supplementary regulations is mandatory. Any violation of the established guidelines may result in disciplinary action, ranging from internal sanctions to termination of employment or commercial contracts, as well as the filing of applicable legal or criminal charges under current regulations.
VERSION CONTROL
| Date | Version | Change Description | Responsible |
| 07/07/2026 | 1.0 | Creación Documento | Andrés García |